PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60724 Oracle CVE debrief

The CVE-2026-60724 vulnerability affects the Oracle Customer Interaction History product, specifically versions 12.2.3-12.2.15. This vulnerability is classified as easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise the product. The potential impact includes unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 5.4, with Confidentiality and Integrity impacts. Users of the affected product versions should apply security updates to prevent unauthorized access. The CVE record was published on 2026-07-21T22:18:12.490Z and has not been modified since then.

Vendor
Oracle
Product
Customer Interaction History
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-19
Advisory published
2026-07-21
Advisory updated
2026-08-19

Who should care

Users of Oracle Customer Interaction History product versions 12.2.3-12.2.15 should apply security updates to prevent unauthorized access. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the risk and implement necessary mitigations. The vulnerability's impact on confidentiality and integrity requires immediate attention to prevent potential data breaches and ensure the security of sensitive information. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected product deployments should be identified in managed environments, and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Monitoring, detection, and logs for exposed assets should be checked for extra review. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Asset inventory and source tracking can help in managing the remediation process effectively. Rollback/change windows should be considered if immediate patching is not feasible. Compensating controls such as restricting network access to the product and monitoring for suspicious activity can help mitigate the risk until patches are applied. The CVE-2026-60724 vulnerability affects Oracle Customer Interaction History product versions 12.2.3-12.2.15, and its exploitation can lead to unauthorized access and data manipulation. Therefore, it is crucial for affected users to prioritize patching and implement additional security measures to protect against potential attacks. Security updates should be applied as soon as possible to prevent exploitation. In addition, defenders should verify the integrity of their systems and monitor for any suspicious activity that could indicate exploitation of this vulnerability. By taking these steps, users can help protect their systems and data from the potential impacts of this vulnerability. Oracle has not

Technical summary

The CVE-2026-60724 vulnerability affects Oracle Customer Interaction History product versions 12.2.3-12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability to compromise the product. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 5.4 with Confidentiality and Integrity impacts.

Defensive priority

Apply security updates to Oracle Customer Interaction History product to prevent unauthorized access.

Recommended defensive actions

  • Apply security updates to Oracle Customer Interaction History product
  • Restrict network access to the product
  • Monitor for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE-2026-60724 vulnerability affects Oracle Customer Interaction History product versions 12.2.3-12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability to compromise the product. Successful attacks can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 5.4 with Confidentiality and Integrity impacts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:12.490Z and has not been modified since then.